CrowdStrike: AI Hack Targets South Korean Banks

A suspected Chinese hacker used artificial intelligence tools, including Anthropic’s Claude Code and a Chinese-developed penetration testing agent, in a series of cyberattacks targeting South Korean financial institutions, cybersecurity firm CrowdStrike reported on October 7, 2026. The campaign targeted at least nine South Korean banks between late September and early October, compromising customer data from thousands of individuals. CrowdStrike said the suspect may be a 26-year-old based in Guangdong province, with personal details discovered while analyzing AI coding-tool sessions and infrastructure associated with the attacks.

AI Tools Deployed in Bank Breaches
CrowdStrike said the individual used ARTEX, a recently released open-source AI agent for automated penetration testing, together with large language models including Claude. ARTEX was published on GitHub in 2026 by a security engineer using the handle Autumn, and functions as a bridge connecting to external large language models such as ChatGPT, Claude, and DeepSeek.
The attacker also used Anthropic’s Claude Code, as well as GLM-5.3 and Grok 4.6 in separate sessions. Session logs recovered from attacker-controlled servers revealed that the suspect asked Claude where stolen Korean data could be sold and sought information about sales channels on platforms like Telegram.

CrowdStrike stated that “the threat actor is likely a Chinese speaker and financially motivated,” making the assessment “with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”
Scope of Customer Data Compromised
Shinhan Bank said information belonging to about 25,000 customers was compromised, while KB Kookmin Bank reported that data from 119 customers was leaked. Hana Bank disclosed 89 affected customers, while BNK said records on 11 outsourced workers were taken.
The exposed records covered names, phone numbers, annual income, and calculated loan limits, and also included 66 resident registration numbers, South Korea’s national ID numbers.

Identity Clues from AI-Generated Resume
In one session, the person requested Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.
A man who answered a phone number published by CrowdStrike in its report said he had no knowledge of the matter. The cybersecurity firm noted that while it identified potential personal details, the activity has not been formally attributed to a named threat actor or group.

Government Response and Investigations
The attacks prompted South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures. Chinese foreign ministry spokesperson Mao Ning told a regular press briefing that the ministry was not familiar with the case and that China as a matter of principle has consistently opposed and combated hacking activities.
Anthropic and South Korean police did not respond to requests for comment.
Growing Concerns Over AI-Enabled Attacks
The breaches raise fresh concerns over the use of AI to automate cyberattacks. While ARTEX’s public repository states it is intended for personal learning, code research, and local technical verification, and warns against targeting online systems, analysts observed it being deployed in the wild.
The incident represents one of the first publicly documented cases in which AI coding assistants and automated penetration testing agents were identified as key tools in a significant financial sector breach. CrowdStrike’s discovery of session logs stored in open directories on attacker-controlled servers provided unusual visibility into how the suspect used AI tools throughout the campaign, from vulnerability discovery to planning data monetization.

Key Facts
- At least nine South Korean banks were targeted in attacks between late September and early October 2026
- Shinhan Bank reported approximately 25,000 compromised customer records; KB Kookmin Bank reported 119 affected customers
- The suspected attacker used ARTEX penetration testing tool alongside Claude Code, GLM-5.3, and Grok 4.6
- CrowdStrike identified a potential suspect as a 26-year-old based in Maoming, Guangdong province, China
- Stolen data included names, phone numbers, income details, and 66 South Korean national ID numbers
- AI session logs revealed the attacker asked Claude where to sell stolen Korean data
Sources
- Infosecurity Magazine: Chinese hacker deployed AI in campaign against South Korean banks
- AJP / Nate News: AI tools linked to cyberattacks on South Korean banks
- The Vibes: AI agents used in cyberattacks targeting South Korean banks, CrowdStrike says
- Reuters via Euronext: South Korean banks were likely hacked by a China-based actor with an AI agent
Sources
- AI agents used in cyberattacks targeting South Korean banks, CrowdStrike says
- South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says
- CrowdStrike Traces South Korean Bank Hacks to China Suspect – Time News
- CrowdStrike Says Suspected Chinese Hacker Used Anthropic’s Claude, AI Agent to Steal South Korean Bank Da – Benzinga
- Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says





